Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-30642

XSS vulnerability in the Office Powerpoint macro (Office Connector)

    XMLWordPrintable

Details

    Description

      To reproduce:
      1. Attach a ".ppt" file to the page. (any file with that extension - doesn't need to be a powerpoint file)
      2. Add "Office Powerpoint" macro with Slide Number as:

      "><script>alert(document.domain)</script>
      

      3. View page.

      See officeconnector, PptConverter.java, line 97.

      Attachments

        Activity

          People

            psaw PatrickA
            djohnson@atlassian.com Dougall Johnson
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: